SAP security note 1596106, "Unauthorized modification of displayed content in CRM Email", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
This security note addresses a vulnerability in CRM One To One Email that allows a malicious user to modify displayed application content without authorization. This could potentially lead to the theft of authentication information from other legitimate users.
Unauthorized modification of displayed content and potential theft of authentication information, which can lead to user impersonation and full compromise of application security.
Solution
Implement the correction provided in SAP Security Note 1596106. Ensure that all correction instructions are followed to mitigate the XSS vulnerability effectively.
References
Full note on SAP: SAP Support Launchpad note 1596106
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
